Impact
A bounds‑check bug in the libata‑scsi implementation caused the kernel to truncate the DATA SET MANAGEMENT (DSM) TRIM descriptor to 2048 bytes, regardless of the logical sector size of the underlying storage device. The descriptor length is then compared against the device’s sector size; when that size is larger than 2048 bytes, the comparison fails, so every TRIM command is rejected with a parameter‑length error. As a result, discard requests are silently ignored and the kernel emits WARN_ON messages on each attempt, effectively disabling TRIM for devices such as 4K‑sector HDDs or SSDs and impairing storage efficiency.
Affected Systems
Linux kernel builds that include libata‑scsi support and are attached to block devices whose logical sector size exceeds 2048 bytes are affected. This includes typical 4 KiB sector devices that many modern systems use. Unpatched systems that rely on automatic discard or that use filesystems with discard enabled will suffer from the loss of TRIM functionality.
Risk and Exploitability
The flaw causes a denial‑of‑service condition that limits the ability of the system to free unused blocks, but it does not provide remote code execution or privilege escalation. The vulnerability requires a local TRIM operation, so the likely attack vector is local or privileged processes, such as the kernel’s automatic discard scheduler. The CVSS score of 8.2 indicates high severity, but the EPSS score of less than 1 % and absence from the CISA KEV catalog suggest that active exploitation is unlikely at present.
OpenCVE Enrichment
Debian DSA